You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Per PEP 458, root metadata should expire every year, so we'll want this value to be at least the number of years we anticipate clients will go between updating their local root metadata, plus some extra rotations in case of a compromise. I actually think that 32 should be plenty.
Please fill in the fields below to submit an issue or feature request. The
more information that is provided, the better.
Description of issue or feature request:
ngclient (like legacy client?) has a
max_root_rotations
value of 32, which feels low.The specification suggests a value of 1024 (2^10)
Can we define a way of calculating a sane default for, i.e., PyPI users and update the default accordingly?
The text was updated successfully, but these errors were encountered: